Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
13.334 exploits
GitHub PoC19
A Nuclei template to detect CVE-2025-29927 the Next.js authentication bypass vulnerability
CVE-2025-29927CRITICAL23 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC4
Next.js Middleware Authorization Bypass
CVE-2025-29927CRITICAL22 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
CVE-2024-49653CRITICAL22 mar 2025
WordPress Portfolleo plugin <= 1.2 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC1
A Bash script to enumerate valid SSH usernames using the CVE-2018-15473 vulnerability. It checks for valid usernames on an OpenSSH OpenSSH 7.2p2 server by analyzing authentication responses.
CVE-2018-15473MEDIUM22 mar 2025
OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticati
70RIESGO
abrir
GitHub PoC2
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
CVE-2024-49668CRITICAL22 mar 2025
WordPress Verbalize WP plugin <= 1.0 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Verify Next.js CVE-2025-29927 on Netlify not vulnerable
CVE-2025-29927CRITICAL22 mar 2025
Authorization Bypass in Next.js Middleware
85RIESGO
abrir
GitHub PoC
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
CVE-2024-52375CRITICAL22 mar 2025
WordPress Datasets Manager by Arttia Creative plugin <= 1.5 - Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC9
Otsmane-Ahmed/CVE-2025-2620-poc
CVE-2025-2620CRITICAL22 mar 2025
D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow
48RIESGO
abrir
GitHub PoC1
A PoC for CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque22 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC4
CVE-2025-24813 Apache Tomcat RCE Proof of Concept (PoC)
CVE-2025-24813CRITICALbajo ataque21 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
wilss0n/CVE-2024-4577
CVE-2024-4577CRITICALbajo ataqueransomware21 mar 2025
Argument Injection in PHP-CGI
100RIESGO
abrir
GitHub PoC2
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
CVE-2025-23922CRITICAL21 mar 2025
WordPress iSpring Embedder plugin <= 1.0 - CSRF to Arbitrary File Upload vulnerability
48RIESGO
abrir
GitHub PoC
Proof-of-concept for In invoke-ai/invokeai version v5.0.2 Arbitrary File Deletion.
CVE-2024-11042CRITICAL21 mar 2025
Arbitrary File Delete in invoke-ai/invokeai
48RIESGO
abrir
GitHub PoC
PoC tool designed to exploit an authenticated Remote Code Execution (RCE) vulnerability in certain versions of PostgreSQL (9.3 - 11.7)
CVE-2019-919320 mar 2025
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
GitHub PoC1
minhluannguyen/CVE-2020-7247-reproducer
CVE-2020-7247CRITICALbajo ataque20 mar 2025
smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to
100RIESGO
abrir
GitHub PoC
The POC and Lab setup documentation of CVE 2021 41773
CVE-2021-41773HIGHbajo ataqueransomware20 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC
POC for CVE-2025-24813 using Spring-Boot
CVE-2025-24813CRITICALbajo ataque20 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
CVE-2012-1823 exploit for https user password website.
CVE-2012-1823CRITICALbajo ataque20 mar 2025
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RIESGO
abrir
GitHub PoC
Resources for teh Apache Tomcat CVE lab
CVE-2025-24813CRITICALbajo ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
Apache Tomcat Vulnerability POC (CVE-2025-24813)
CVE-2025-24813CRITICALbajo ataque19 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware19 mar 2025
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
GitHub PoC2
Koha CVE-2025-22954: SQL Injection in lateissues-export.pl
CVE-2025-22954CRITICAL19 mar 2025
GetLateOrMissingIssues in C4/Serials.pm in Koha before 24.11.02 allows SQL Injection in /serials/lateissues-export.pl vi
53RIESGO
abrir
GitHub PoC
CVE-2018-7600.
CVE-2018-7600CRITICALbajo ataqueransomware19 mar 2025
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RIESGO
abrir
GitHub PoC
Windows File Explorer Spoofing Vulnerability (CVE-2025-24071)
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC2
Alternativa CVE-2025-24071_PoC
CVE-2025-24071MEDIUM19 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC
HUSKY – Products Filter Professional for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion (LFI)
CVE-2025-1661CRITICAL18 mar 2025
HUSKY – Products Filter Professional for WooCommerce <= 1.3.6.5 - Unauthenticated Local File Inclusion
75RIESGO
abrir
GitHub PoC25
Metasploit module for CVE-2025-24071 - Windows NTLM Hash Leak via .library-ms
CVE-2025-24071MEDIUM18 mar 2025
Microsoft Windows File Explorer Spoofing Vulnerability
38RIESGO
abrir
GitHub PoC5
Apache Tomcat Remote Code Execution (RCE) Exploit - CVE-2025-24813
CVE-2025-24813CRITICALbajo ataque18 mar 2025
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
100RIESGO
abrir
GitHub PoC1
Checkmarx/Checkmarx-CVE-2025-30066-Detection-Tool
CVE-2025-30066HIGHbajo ataque18 mar 2025
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 thr
93RIESGO
abrir
GitHub PoC1
iOS/macOS library that exploits CVE-2023-41991 for signing iOS applications.
CVE-2023-41991MEDIUMbajo ataque18 mar 2025
A certificate validation issue was addressed. This issue is fixed in macOS Ventura 13.6, iOS 16.7 and iPadOS 16.7. A mal
63RIESGO
abrir
anteriorpágina 164 / 445siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.